Impact
Concrete CMS versions earlier than 9.5.3 register view assets for every sub‑block within a Stack, Container, or layout area without verifying that the requesting user has permission to view that sub‑block. The process emits configuration values, such as a site’s Google Maps API key, which can then be retrieved by any visitor of a public page that contains an affected Stack, Container, or layout area. The vulnerability is a direct result of missing authorization checks and allows an attacker to read sensitive configuration data that should be protected at the block level. This leads to the disclosure of potentially critical information, which can be used to facilitate further attacks, such as API abuse or privilege escalation. The weakness is classified under CWE-862, Missing Authorization.
Affected Systems
Concrete CMS installations running a version earlier than 9.5.3 are affected. The vulnerability applies to any sub‑block type whose asset or header hooks output configuration values. Public pages that embed an affected Stack, Container, or layout area provide a path to exploitation.
Risk and Exploitability
The CVSS v4.0 score is 6.3, indicating a medium severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need authentication or special privileges; any unauthenticated visitor to a public page containing an affected block can trigger the vulnerability and retrieve restricted configuration data. The risk is therefore moderate, with potential for significant impact if sensitive values are exposed.
OpenCVE Enrichment